Privacy Policy
Last updated: September 29, 2026
1. Information We Never Collect or Process
- We never collect, store, or transmit generated Primary Account Numbers (PANs), security codes (CVVs), or synthetic cardholder details.
- We never transmit input entered into the Card Validator or Luhn Checker tools. All validation logic runs locally via pure JavaScript.
- We never request or store real credit card numbers, passwords, PINs, or banking credentials.
- We never persist generated card datasets in browser storage (localStorage, sessionStorage, cookies, or IndexedDB).
2. Safe BIN/IIN Lookups
The Bank Identification Number (BIN) lookup tool is restricted to 6 to 8 digits only. It verifies high-level card scheme metadata and Major Industry Identifiers (MII) locally. We never store, transmit, or correlate lookup queries with identifiable user sessions.
3. Web Analytics & Cookies
Analytics is disabled in local development and staging. In production, Google Analytics loads only after a visitor explicitly selects “Allow analytics.” Rejecting the prompt prevents the analytics script from loading. Analytics configuration is limited to aggregate page usage and never includes card-tool inputs, generated PANs, CVVs, BIN queries, validation values, or synthetic profiles.
We store only two non-sensitive browser preferences in localStorage: the selected light/dark theme and the analytics consent choice. Generated card data and validator inputs are never written to browser storage.
4. Third-Party Advertising & DART Cookies
No advertising script is currently active. Development placeholders are excluded from static production builds. If advertising is introduced later, this policy and the consent controls must be updated before an advertising script is enabled. Such vendors may use cookies, web beacons, or similar technologies only under the applicable consent and provider configuration:
- Third-party vendors, including Google, use cookies to serve ads based on a user's prior visits to this website or other sites on the Internet.
- Google's use of advertising cookies enables it and its partners to serve relevant ads based on browsing patterns.
- Users may opt out of personalized advertising by visiting Google Ads Settings.
- You can also opt out of third-party vendor cookies for personalized advertising through the Digital Advertising Alliance Consumer Choice tool or the Network Advertising Initiative Opt-Out.
- Generated test card data, Luhn calculations, and validation inputs are never shared with or accessible to third-party advertising networks.
5. Security Practices
Production uses HTTPS and standard browser security headers, including content-type protection, framing restrictions, a strict-origin referrer policy, and a Content Security Policy. These controls reduce common browser risks but do not replace secure development and dependency review.